
Critical Vulnerability Discovered in Grist-Core Open-Source Spreadsheet Database
CybersecurityVulnerabilitiesRemoteCodeExecutionOpenSourceDatabaseSecuritySelfHosted
A critical flaw has been identified in Grist-Core, an open-source and self-hosted relational database in spreadsheet form. Tracked as CVE-2026-24002 with a CVSS score of 9.1, this vulnerability, dubbed Cellbreak by Cyera Research Labs, enables remote code execution (RCE) through malicious formulas in a spreadsheet. No details regarding the disclosure date or affected versions have been specified. The potential impact includes full compromise of the system hosting the application.